Page |1
Enterprise - Exam 2 Questions and Correct
Answers/ Latest Update / Already Graded
A process of grouping almost identical alarms that occur nearly at the
same time into a single higher-level alarm is known as alarm _____.
Ans: clustering
A unique value or pattern of an attack that enables detection is called
a(n) _____.
Ans: signature
A ____ rootkit is one that becomes a part of the system bootstrap
process and is loaded every time the system boots.
Ans: persistent
A(n) ____ is a type of IDPS that is similar to an NIDPS; it reviews the log
files generated by servers, network devices, and even other IDPSs.
Ans: log file monitor
A(n) ____ is any system resource that is placed in a functional system
but has no normal use in that system. If it attracts attention, it is from
unauthorized access and will trigger a notification or response.
All rights reserved © 2025/ 2026 |
, Page |2
Ans: honeytoken
A(n) ____ is the set of rules and configuration guidelines governing the
implementation and operation of IDPSs within the organization.
Ans: site policy
An advantage of an HIDPS is _____.
Ans: it functions on the host system, where encrypted traffic is
decrypted and available for processing
By guarding against some types of vulnerabilities, an IDPS can become
an important part of an organization's _____ strategy.
Ans: defense in depth
In an attack known as ____, valid protocol packets exploit poorly
configured DNS servers to inject false information and corrupt the
servers' answers to routine DNS queries from other systems on that
network.
Ans: DNS cache poisoning
All rights reserved © 2025/ 2026 |
, Page |3
Like the Wiretap Act's prohibition on intercepting the contents of
communications, the _____ creates a general prohibition on the real-
time monitoring of traffic data relating to communications.
Ans: Pen/Trap statute
The ongoing activity from alarm events that are accurate and
noteworthy but not necessarily as significant as potentially successful
attacks is called ____.
Ans: noise
The process of classifying the attack alerts that an IDPS detects in
order to distinguish or sort false positives from actual attacks more
efficiently is known as alarm _____.
Ans: filtering
The SIEM capability of _____ enables flexible and timely reaction to
attacks
Ans: real-time monitoring
The SIEM capability of _____ enables review of system activity that can
identify breaches and reveal insider misuse.
Ans: user monitoring
All rights reserved © 2025/ 2026 |
Enterprise - Exam 2 Questions and Correct
Answers/ Latest Update / Already Graded
A process of grouping almost identical alarms that occur nearly at the
same time into a single higher-level alarm is known as alarm _____.
Ans: clustering
A unique value or pattern of an attack that enables detection is called
a(n) _____.
Ans: signature
A ____ rootkit is one that becomes a part of the system bootstrap
process and is loaded every time the system boots.
Ans: persistent
A(n) ____ is a type of IDPS that is similar to an NIDPS; it reviews the log
files generated by servers, network devices, and even other IDPSs.
Ans: log file monitor
A(n) ____ is any system resource that is placed in a functional system
but has no normal use in that system. If it attracts attention, it is from
unauthorized access and will trigger a notification or response.
All rights reserved © 2025/ 2026 |
, Page |2
Ans: honeytoken
A(n) ____ is the set of rules and configuration guidelines governing the
implementation and operation of IDPSs within the organization.
Ans: site policy
An advantage of an HIDPS is _____.
Ans: it functions on the host system, where encrypted traffic is
decrypted and available for processing
By guarding against some types of vulnerabilities, an IDPS can become
an important part of an organization's _____ strategy.
Ans: defense in depth
In an attack known as ____, valid protocol packets exploit poorly
configured DNS servers to inject false information and corrupt the
servers' answers to routine DNS queries from other systems on that
network.
Ans: DNS cache poisoning
All rights reserved © 2025/ 2026 |
, Page |3
Like the Wiretap Act's prohibition on intercepting the contents of
communications, the _____ creates a general prohibition on the real-
time monitoring of traffic data relating to communications.
Ans: Pen/Trap statute
The ongoing activity from alarm events that are accurate and
noteworthy but not necessarily as significant as potentially successful
attacks is called ____.
Ans: noise
The process of classifying the attack alerts that an IDPS detects in
order to distinguish or sort false positives from actual attacks more
efficiently is known as alarm _____.
Ans: filtering
The SIEM capability of _____ enables flexible and timely reaction to
attacks
Ans: real-time monitoring
The SIEM capability of _____ enables review of system activity that can
identify breaches and reveal insider misuse.
Ans: user monitoring
All rights reserved © 2025/ 2026 |